CVE-2025-1247: Red Hat Build Of Apache Camel 4.8 For Quarkus 3.15

High severity, CVSS 8.3. EPSS: 0.8% chance of exploitation in the next 30 days.

A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or access sensitive information.

Affected products

  • Red Hat Red Hat Build Of Apache Camel 4.8 For Quarkus 3.15
  • Red Hat Red Hat Build Of Quarkus 3.15.3.sp1
  • Red Hat Red Hat Build Of Quarkus 3.8.6.sp3

Published 2025-02-13. Last modified 2026-08-04.